PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54645 cubecart CVE debrief

CubeCart 6.7.4 and earlier versions have a stored cross-site scripting (XSS) vulnerability in the product description, short description, and spec_copy fields. An administrator with product-editing rights can store malicious JavaScript code that bypasses the filter, leading to persistent JavaScript execution when a storefront visitor or another administrator views the product content.

Vendor
cubecart
Product
v6
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-22
Advisory published
2026-09-17
Advisory updated
2026-09-22

Who should care

Administrators and security teams responsible for CubeCart installations should assess exposure and prioritize updating to version 6.7.5 or later to prevent exploitation. They should also review product content for suspicious code and monitor for suspicious activity on the storefront and administrative interfaces. Additionally, operators and platform administrators should be aware of the potential impact on their systems and take steps to verify their 6.7.

Why it matters

The CVE-2026-54645 vulnerability in CubeCart allows administrators with product-editing rights to store malicious JavaScript code, leading to persistent JavaScript execution. Defenders should prioritize updating to version 6.7.5 or later and review product content for suspicious code.

  • Session exposure or unauthorized browser-context actions may occur when a storefront visitor or another administrator views the product content.
  • Persistent JavaScript execution can lead to unauthorized actions or data exposure.
  • Defenders should verify the scope of affected versions and exploitation.

Technical summary

The CubeCart ecommerce software solution prior to version 6.7.5 has a stored cross-site scripting (XSS) vulnerability. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass the filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content. This vulnerability allows administrators with product-editing rights to store malicious JavaScript code, leading to persistent JavaScript execution. The vulnerability affects the product description, short description, and spec_copy fields.

Defensive priority

Administrators and security teams should prioritize updating to version 6.7.5 or later to prevent exploitation.

Recommended defensive actions

  • Update to CubeCart version 6.7.5 or later
  • Review product descriptions, short descriptions, and spec_copy fields for malicious code
  • Monitor for suspicious activity on the storefront and administrative interfaces
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD vulnerability detail provide information on the vulnerability. However, the exact scope of affected versions and exploitation is not explicitly stated. Defenders should verify the scope of affected versions, review product content for suspicious code, and monitor for suspicious activity on the storefront and administrative interfaces. The lack of explicit information on affected versions and exploitation requires defenders to take a cautious approach and thoroughly review their systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54645 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54645

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54645 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54645

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.